CVE-2026-33725 | Metabase up to 1.59.3 Serialization Import Endpoint import deserialization (GHSA-fppj-vcm3-w229 / Nessus ID 304390)
A vulnerability labeled as problematic has been found in Metabase up to 1.59.3. This affects an unknown function of the file /api/ee/serialization/import of the component Serialization Import Endpoint. The manipulation results in deserialization.
This vulnerability is known as CVE-2026-33725. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.